Connect with us

E-Business

Financial Sector Faced AI, Blockchain and Organised Crime Threats in 2025 – Report

Published

on

Kindly share this post

The 2025 Kaspersky Security Bulletin provides a review of the major cybersecurity trends of the year and offers a look towards the future of cybersecurity, including within the financial sector.

According to the report, in 2025, the financial sector navigated a rapidly evolving cyber landscape, with malware spreading through messaging apps, AI-assisted attacks, supply chain compromises, and NFC-based fraud.

Based on Kaspersky Security Network statistics for the year (from November 2024 to October 2025), 8.15% of users in the finance sector globally faced online threats and 15.81% faced local (on-device) threats. 1,338,357 banking trojan attacks were detected by the company’s solutions. 12.8% of B2B finance sector companies faced ransomware this year – that marks a 35.7% increase in unique users in 2025 compared to the same period of 2024.

The company’s experts highlight the following cybersecurity trends and cases shaping the financial sector in 2025:

Large-scale supply chain attacks: the financial sector faced a series of unprecedented supply chain attacks, which are incidents that exploit vulnerabilities in third-party providers to reach their primary targets. The breaches demonstrated how vulnerabilities in third-party providers can cascade through national payment networks, affecting even central systems.

Advertisement

Organised crime converging with cybercrime: organised crime is increasingly combining physical and digital methods, creating more sophisticated and coordinated attacks. Financial institutions faced threats that blend social engineering, insider manipulation, and technical exploitation.

Old malware, new channels: cybercriminals increasingly exploit popular messaging apps to spread malware, shifting from email phishing to social channels. Banking trojans are being rewritten to use messaging platforms as a new distribution vector, enabling large-scale infections.

AI scales malware to new heights: this year, AI-enabled malware has increasingly incorporated automated propagation and evasion techniques, allowing attacks to spread faster and reach a larger number of targets. This automation also shortens the time between malware creation and deployment.

Mobile banking attacks and NFC fraud: Android malware using ATS (Automated Transfer System) techniques automate fraudulent transactions, altering transfer amounts and recipients in real time without the user noticing. NFC-based attacks have also emerged as a key trend, enabling both physical fraud in crowded places and remote fraud via social engineering and fake apps mimicking trusted banks.

Blockchain-Based C2 Infrastructure is on the rise: crimeware attackers increasingly embed malware commands in blockchain smart contracts, targeting Web3 to steal cryptocurrencies.

Advertisement

This method ensures persistence and makes the infrastructure extremely difficult to remove. Using blockchain for C2 operations allows attackers to maintain control even if conventional servers are shut down, highlighting a new level of resilience in cyberattacks.

Ransomware presence: these types of attacks remained a persistent threat for the financial sector with 12.8% of B2B finance organisations globally affected in November 2024 through October 2025. The figure for Africa is similar, with 12.9% of B2B finance organisations affected by ransomware from November 2024 through October 2025.

Disappearance of certain malware families: some malware families are likely to disappear, as their activity depends directly on the operations of specific criminal groups.

“In 2025, financial cyber threats evolved into a complex landscape, with attacks hitting businesses and end users alike. Criminal groups increasingly combined digital tools, insider access, AI and blockchain to scale operations, forcing organisations to secure not only their systems but also the human networks that support them,” said Fabio Assolini, Head of the Americas & Europe units at Kaspersky GReAT.

Kaspersky’s predictions for what finance cybersecurity might face in 2026, include:

Advertisement

Banking Trojans will be rewritten for WhatsApp distribution: criminal groups will increasingly rewrite and scale banking trojans distribution and abuse messaging apps like WhatsApp to target corporate and government organisations that still rely on desktop-based online banking. These environments are where Windows-based banking trojans thrive.

Growth of deepfake/AI services for social engineering: the trade in realistic deepfakes and AI-powered campaigns is expected to expand even more, fueling scams around job interviews and offers, driving underground demand for tools that fully bypass Know Your Customer (KYC) verification.

Appearance of regional info stealers: as Lumma, Redline and other stealers are still active, we expect to see the appearance of regional info stealers, targeting specific countries or regions, expanding the use of malware-as-a-service model.

More attacks on NFC payments: as a key technology used in payments, we’ll see more tools, more malware and attacks directed against NFC payments, in all types.

The advent of Agentic AI malware: agentic AI malware is characterised by its ability to dynamically alter behaviour mid-execution. Unlike conventional malware that relies on pre-defined instructions, agentic variants are designed to assess their environment, analyse their impact, and adapt their tactics on the fly.

Advertisement

This means that a single piece of malware could exhibit a range of behaviours, from initial infiltration to data exfiltration or system disruption, all in response to the specific defences and vulnerabilities it encounters.

Classic fraud will obtain new delivery: fraud will remain a major threat to end users, but its delivery methods will keep evolving. As new services and messaging platforms emerge, attackers will continue to adapt their tactics to the channels where their target audience is most active.

The persistence of ‘out of box’, pre-infected devices: the threat of counterfeit smart devices sold already infected with trojans (such as Triada) will continue to evolve.

These trojans often come with extensive capabilities, including the ability to steal banking credentials, and affect not only “gray” Android smartphones but also other smart devices such as TVs.

 

Advertisement

Kindly share this post

Dear Reader, Your support matters. But we believe that technology makes life more exciting and helps improve the lives of people around Nigeria and indeed the world. That is why, we have devoted our energy to independent reportage of technology and finance and how they affect lives. Our incisive and analytical view of how technology news affects the daily life help individuals and organizations make up their minds. Quality journalism costs money. Today, we're asking that you support us to do more. Kindly support our effort to deliver technology and finance journalism to everyone in the world. Donate as little as N1,000. Bank transfers can be made to: UBA Plc 1017156876 Communication Week Media Ltd

E-Business

Firm Advocates Healthy IT Habits to Strengthen Cyber Resilience

Published

on

Kindly share this post

At the recent Cyber Security Weekend 2026 conference, Kaspersky shared the findings from its survey titled “Cybersecurity in the workplace: Employee knowledge and behaviour” which was conducted among employees from the Middle East, Turkiye and Africa (META) region.

The study highlights that everyday IT habits, including decluttering computers and reducing digital fatigue, can have a direct and often underestimated impact on an organisation’s cyber resilience.

The Kaspersky survey points to a growing challenge of digital fatigue in the workplace. 13.5% of employees surveyed in the META region confirmed that they made IT-related mistakes due to a lack of cybersecurity knowledge – a figure that shows the critical importance of continuous cybersecurity training and awareness programmes.

Among other reasons behind IT mistakes, respondents cited being in a hurry (30%), oversight (14%), being tired or stressed (12.9%) and having too many notifications (10%). The constant barrage of alerts, messages, and on-screen clutter is becoming an acute problem that can lead to costly IT errors, overlooked social engineering attacks, and even to cyber breaches.

The survey also examined employees’ digital workspace habits. An overwhelming 44.5% of respondents in the META region reported having between 10 and 20 icons on their desktop, while 30% admitted to having even more – with half to a full screen covered in them.

Advertisement

Meanwhile, 33% of respondents also keep more than 10 tabs open in their browser at any given time. Excessive icons and open tabs do more than distract attention and fuel procrastination – they can slow device performance and, in the case of unused applications, quietly collect data.

Interestingly, most employees regularly disinfect their keyboards and phone surfaces (21.5% have adopted this habit since the COVID pandemic). However, digital cleanliness has not kept pace: 55% of respondents remove needless files once a month or more often; the rest perform digital clean-ups far less frequently – once a quarter, or even once a year.

Managing digital noise is key to staying alert: only essential notifications should remain active, especially during periods of deep focus on critical project deliverables. Regular breaks are just as vital for maintaining both well-being and cyber vigilance.

According to the survey, 78% of respondents spend their work breaks eating or drinking, while 58% chat with friends and colleagues. However, stretching and physical exercise is a more effective way to relieve stress and recharge focus – a habit adopted by only 14% of employees.

“It is important to recognise that digital fatigue is a real and growing stress factor: the constant stream of notifications, cluttered screens, and information overload gradually erode focus and make employees far more susceptible to mistakes and social engineering attacks. Simplifying your digital environment is not just a productivity tip, it is a cybersecurity measure”, says Brandon Muller, senior security consultant for the META region at Kaspersky.

Advertisement

Kindly share this post
Continue Reading

E-Business

Extremist Groups Are Using Social Media to Recruit African Youth, New Report Warns

Published

on

Kindly share this post

Pan-African digital rights organisation Paradigm Initiative (PIN) has warned that violent extremist groups are increasingly exploiting digital platforms to recruit, radicalise and manipulate young people across the Sahel region.

Extremist Groups Are Using Social Media to Recruit African Youth, New Report Warns

The organisation raised the concern in a new policy brief titled “Digital Frontlines: Countering Online Radicalisation and Violent Extremist Narratives in the Sahel.”

According to the publication, extremist groups are shifting from traditional recruitment methods to digital platforms, including social media, encrypted messaging applications, short-form video platforms and online financial incentives, to target vulnerable populations.

PIN noted that unemployed youths and people facing insecurity and limited economic opportunities are particularly susceptible to online recruitment campaigns.

The organisation said that although governments have intensified efforts to combat violent extremism, responses to the digital dimension of the threat have failed to keep pace with rapidly evolving online tactics.

Advertisement

It argued that addressing online radicalisation requires more than surveillance and restrictive measures, recommending investments in digital literacy, stronger community resilience, improved early-warning systems and credible counter-narratives.

PIN also urged governments to work closely with technology companies and civil society organisations to disrupt extremist recruitment while protecting citizens’ digital rights.

The report further highlighted the growing convergence between organised crime and violent extremist groups, noting that online propaganda increasingly promises financial rewards, belonging and purpose to vulnerable young people.

According to the organisation, this trend underscores the need for policymakers to prioritise prevention alongside conventional security responses.

Speaking on the findings, Moussa Waly SENE, Programmes Officer for Francophone Africa at Paradigm Initiative, described the digital space as a new frontline in the fight against violent extremism.

Advertisement

“As more young Africans come online, stakeholders must ensure that digital platforms remain spaces for opportunity, innovation and civic participation, not recruitment grounds for violent extremist groups. Protecting digital rights and protecting vulnerable communities should be mutually reinforcing objectives,” he said.

Among its recommendations, the policy brief called for stronger regional cooperation to tackle cross-border online extremist networks, rights-respecting content moderation and greater accountability by digital platforms.

It also advocated expanded digital literacy programmes to strengthen resilience against online manipulation and community-led initiatives that empower young people to identify and reject extremist narratives.

The organisation further urged policymakers to develop security measures that balance national security objectives with the protection of privacy, freedom of expression and access to information.

Advertisement

Kindly share this post
Continue Reading

E-Business

Kaspersky Reveals a New Malicious Framework Targeting Cryptocurrency Users with the Use of OkoSpyware

Published

on

Kindly share this post

At its recent annual Cyber Security Weekend for the Middle East, Turkiye and Africa (META) region, Kaspersky Global Research and Analysis Team (GReAT) shared insights about the new OkoBot campaign targeting cryptocurrency users.

The new sophisticated framework employs TookPS to exfiltrate seed phrases and uses a new OkoSpyware module to monitor Chromium-based browsers and deploy various malware strains, including the Rilide stealer.

It has already targeted hundreds of victims across over 25 countries, with the highest number of affected end users recorded in Brazil, Vietnam, Canada, Mexico and Turkiye. According to Kaspersky experts, the threat remains active and primarily poses a risk to cryptocurrency users.

In January 2026, experts from the Kaspersky Global Research and Analysis Team (GReAT)  identified multiple attacks involving a previously unknown malware capable of capturing the contents of cryptocurrency wallet windows. Dubbed Okobot, the new sophisticated malware framework comprises more than 20 malicious payloads and implants designed to perform a wide range of functions, including collecting local files, executing remote commands, downloading arbitrary browser extensions, stealing cryptocurrency wallets, harvesting seed phrases and credentials, recording video and carrying out other malicious activities.

One of the new implants used in the campaign is a loader that modifies browser memory to load and hide malicious extensions. OkoBot also includes a new OkoSpyware module, which captures keystrokes and the video stream of a target application’s window.

Advertisement

Currently available information does not allow the campaign to be attributed to any known crimeware actor with high confidence. However, the techniques and infostealer involved are widely used by Russian-speaking threat actors, and technical analysis has also revealed code artifacts in Russian.

The initial infection typically occurs through two main vectors: ClickFix attacks, in which threat actors use social engineering to trick users into running malicious code, and malware distributed via GitHub under the guise of legitimate software. During the investigation, researchers identified one such case involving a fake installer for SQL Server Management Studio (SSMS), a widely used Microsoft database management tool.

The malicious framework includes SeedHunter, a malware component that monitors active system processes and injects an implant into Trezor Suite, Ledger Wallet, and Ledger Live, – official applications used to manage cryptocurrency assets. When it detects a connected Trezor or Ledger hardware wallet, it triggers the hooked functions to display a hard-coded phishing page aimed at stealing the user’s seed phrase, using a distinct layout for each wallet type.

“The OkoBot campaign has been active for more than a year and remained ongoing as of July 2026. The observed infection vectors strongly suggest that developers are among its primary targets. Of particular concern is the malware’s continued evolution, which indicates that the framework is being actively maintained. As distribution efforts persist, the campaign has the potential to reach more users and expand into additional countries in the near term,” says Dmitry Galov, Head of the Russia and CIS unit at Kaspersky Global Research and Analysis Team.

Advertisement

Kindly share this post
Continue Reading

Trending